Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\SysCommander] 'Start' = '00000002'
- 'C:\Drivers\cache\svchost.exe'
- 'C:\Drivers\cache\svchost.exe' -install
- '<SYSTEM32>\attrib.exe' +s +h c:\Drivers
- '<SYSTEM32>\cmd.exe' /c ""C:\Drivers\cache\frts.bat" "
- '<SYSTEM32>\wscript.exe' "c:\Drivers\cache\md.vbs"
- C:\Drivers\cache\md.vbs
- C:\Drivers\cache\Debug_20130627.log
- C:\Drivers\cache\svchost.exe
- C:\Drivers\cache\Sysconfig.dll
- C:\Drivers\cache\frts.bat
- C:\Drivers\cache\md.vbs
- 'fo###t-fire.net':21
- DNS ASK fo###t-fire.net
- ClassName: 'Shell_TrayWnd' WindowName: '(null)'
- ClassName: 'EDIT' WindowName: '(null)'